Sceawere
Vulnerability Detail
CVE-2026-108863UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Katanemo Plano Unauthorized Envoy Access
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Katanemo
- Product
- Plano
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces on port 9901. Attackers can request the /config_dump endpoint to read configured LLM provider API keys in plaintext from the WASM filter configuration.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-11T14:17:06.360Z",
"pubdate": "2026-10-11T14:17:06.360Z",
"executiveSummary": "Katanemo Plano versions through 0.4.37 are susceptible to a critical missing authentication vulnerability affecting the Envoy admin interface. The interface is improperly configured to bind to all host interfaces on port 9901, exposing sensitive internal configuration data to any unauthenticated network actor.\nThe primary risk involves the unauthorized extraction of LLM provider API keys stored in plaintext within the WASM filter configuration. Because the Envoy admin interface is exposed globally without authentication, attackers can remotely query the /config_dump endpoint to retrieve these credentials. Successful exploitation leads to a complete compromise of configured LLM provider integrations, potentially resulting in unauthorized resource consumption, data exfiltration, or financial impact associated with API usage. The vulnerability does not require prior authentication or specialized privileges, making it highly accessible to external network-adjacent attackers.",
"technicalDetails": "The vulnerability resides in the network configuration of the Envoy proxy component integrated within Katanemo Plano. In affected versions (0.4.37 and earlier), the Envoy admin interface is bound to the wildcard address (0.0.0.0) on TCP port 9901, rather than being restricted to the loopback interface (127.0.0.1) or protected by access control lists (ACLs). This misconfiguration renders the administrative port accessible from any network segment that can route to the host, bypassing the intended security boundaries.\nThe attack flow begins with the reconnaissance of the target infrastructure to identify active TCP listeners on port 9901. Once the Envoy admin interface is identified, an unauthenticated attacker can interact directly with the administrative HTTP server. The core of the exploitation involves targeting the /config_dump endpoint, which serves as a diagnostic tool designed to return the full current configuration state of the Envoy proxy.\nWithin the context of Katanemo Plano, the WASM filter configurations utilized for LLM orchestration are included in the output generated by the /config_dump endpoint. These configurations contain hardcoded or plaintext API keys intended for authentication with third-party LLM providers. Because the admin interface lacks an authentication requirement or rate-limiting mechanism for this sensitive endpoint, the attacker can execute a simple HTTP GET request to receive the full configuration object.\nThe post-exploitation impact is severe, as the attacker effectively gains access to the same credentials used by the application to interact with LLM backends. By exfiltrating these keys, an attacker can impersonate the Katanemo Plano instance in interactions with the provider, leading to potential account hijacking, unauthorized billing, or the interception of proprietary prompts and data sent to the LLM service. The absence of authentication at the protocol level ensures that no logs or session tokens are required to complete the theft, simplifying the execution for automated scanning tools and remote adversaries alike."
}